- This is certified documentation and is protected for editing by Zimbra Employees & Moderators only.

- This article is a Work in Progress, and may be unfinished or missing sections.

Only one master LDAP server can exist and this LDAP server is authoritative for user information, server configuration, etc. The instructions that follow explain how to promote a replica LDAP server to master and disable the previous LDAP master.

Promoting a Replica Server – Demoting the Master Server

Before you can promote a replica LDAP server to become the master LDAP server, your LDAP replication servers must be up and working correctly; that is the replica LDAP server(s) must be receiving LDAP updates from the master. See the Multi-Server Installation Guide, LDAP Replication Installation chapter.

j. On all the other servers, update zmlocalconfig -e ldap_url to remove the old master server. It should already include the new one.

k. On the replicas, run ldap start

l. Use the tool zmldapreplicatool to update the LDAP Master URI in the syncrepl configuration for each replica (ZCS 7.x only)

m. Update the passwords stored in localconfig for the amavis, postfix, and nginx users to match the values stored in localconfig on the old master. This will ensure that if you run a ZCS upgrade on the new master, the passwords are preserved correctly.

3. Now you run zmmtainit on the MTA servers to edit the ldap*.cf files in /opt/zimbra/conf to set the new master LDAP server as the authority for the MTA. These files tell Postfix how to connect to the LDAP server for various commands. If you are moving the directories, you might have Postfix pointing to a server that no longer runs LDAP, which will cause mail delivery to stop.

Note: zmmtainit should be run on the hosts that are running an MTA, but is not required on the other hosts.

As zimbra, type the following. The "XX" is a dummy value. The zmmtainit command will use the ldap_url value from localconfig in spite of this.

/opt/zimbra/libexec/zmmtainit XX

4. Start the new LDAP master, type zmcontrol start. Then start up the services on all the other servers. At this point, services should be up and running on all hosts, and they should all be working off the new Master LDAP server.

Note: After the replica is promoted to Master, you should verify that the backup schedule is correctly set. Run zmschedulebackup -q. The schedule should match the backup schedule on the Mail Stores. If the backup schedule does not, run the zmschedulebackup command to set the backup schedule.